Re: PHP File Upload Security Hole - Still No Fix?
| From: | Rasmus Lerdorf | Date: | Tue, 05 Sep 2000 14:43:25 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32183@lists.php.net to get a copy of this message | ||
On Tue, 5 Sep 2000, Jon Ribbens wrote:
> Rasmus Lerdorf <rasmus@php.net> wrote:
> > It was a usage difference. You said the function was completely
> > useless. I said it was quite useful the way I have always used it. ie.
> >
> > $a = "a;b";
> > $b = "c;d";
> > $a = escapeshellcmd($a);
> > $b = escapeshellcmd($b);
> > system("ls $a $b");
>
> As I said at the time, this is broken. Try '$a = "a b"' and see what you
> get.
You get: ls a b
This does not let anybody escape out of the shell command.
-Rasmus